Key takeaways
- Anthropic launched OSS Scanner on October 8, 2026. Core maintainers of eligible open-source projects can apply now by adding a project configuration through a pull request to the public anthropics/oss-scanner repository.
- The service is free and periodic, but it is not an API or a self-serve scanner. Anthropic selects projects case by case, verifies maintainers and does not publish a guaranteed acceptance time, scan cadence, report volume, service level or capacity.
- Reports come directly from Anthropic’s strongest models, including Claude Mythos, without human review or triage. Anthropic says each report includes a reproducer, explanation and candidate patch when available; maintainers remain responsible for validation and prioritization.
- Anthropic reports that 85 of 97 selected critical or high-severity pilot findings across 48 projects met its coordinated-disclosure bar; 11 of the other 12 were real duplicates or known findings and one was invalid. This is a vendor-run, selected-sample result, not an independent false-positive rate for future scans.
- Apply only if the project already has capacity to handle verified high and critical reports. Use a dedicated public security alias, provide a precise threat model, reproduce every finding in a controlled environment and treat proposed patches as untrusted changes until reviewed and tested.
Anthropic opened OSS Scanner enrollment on October 8
Anthropic announced OSS Scanner on October 8, 2026 as an opt-in vulnerability-finding service for open-source software. The live enrollment repository makes the offer actionable now: a core maintainer opens a pull request under projects/<name> with project configuration and build instructions. Anthropic says it will verify maintainer status and decide eligibility case by case.
The target is established software with critical impact on infrastructure or user security, particularly projects exposed to remote attacks or widely depended upon. Anthropic says accepted projects receive thorough, periodic scans at no cost. It does not publish an API, local scanner binary, model ID, guaranteed admission date, scan interval, finding quota, regional scope or service-level commitment.
The reports are fast because human triage is removed
OSS Scanner sends enrolled maintainers fully model-generated reports from Anthropic’s strongest models, including Claude Mythos. The launch post says a report can contain a self-contained reproducer, an explanation and bisection where possible, plus a candidate patch when available. The repository says delivery is by email to the primary contact and optional CCs.
The decisive caveat is that Anthropic does not review or triage these reports before delivery. The company explicitly says findings can be incorrect or invalid. It also warns that severity can be inflated and that the scanner may misunderstand a project’s threat model. This is a queue-acceleration service, not a transfer of verification responsibility.
The pilot evidence is promising but provider-reported
Anthropic says expert penetration testers checked 97 critical and high-severity findings from an early scanner version across 48 projects. It reports that 85, or 88%, met the bar for its coordinated vulnerability disclosure process; of the remaining 12, 11 were real but duplicated known issues or other scan findings, while one was invalid. Anthropic also quotes wolfSSL saying 72 of 74 reports it received were valid and five became CVEs.
Those figures should not be converted into a universal precision claim. Anthropic selected the severity bands and sample, ran the pipeline, chose the evaluation bar and published the result. The launch page does not provide the project list, sampling frame, complete finding set, per-language results, assessor protocol or future-version guarantee. Treat the numbers as vendor evidence that justifies a controlled trial, not proof that every report is correct.
The service is distinct from coordinated disclosure and Claude Security
Anthropic’s coordinated vulnerability disclosure pipeline still uses external security firms to reproduce and assess findings before reporting confirmed issues. Its dashboard, last updated October 2, lists 29,439 candidates, 6,123 externally reviewed findings and 5,674 confirmed valid findings. It also lists 6,157 total reports to maintainers, 516 patched upstream and 584 CVE or GHSA identifiers. These are vendor-maintained counts across the broader program, not measured OSS Scanner outcomes.
OSS Scanner is the optional fast track for maintainers willing to receive raw reports sooner. Anthropic says it will not apply a 90-day public-disclosure period to those unreviewed findings and will not publish them. Claude Security is a separate general-access scanning and patching product aimed at enterprises; OSS Scanner is the no-cost program for eligible open-source projects.
Enrollment requires a reproducible offline build
The application requires a repository URL, public primary-contact email and a Dockerfile. Maintainers can add CC addresses, a homepage, an OpenPGP public key and a threat-model path. Email addresses entered in project.yaml are public, so a role-based security address is safer than a personal inbox. The configuration also supports pausing reports or withdrawing the project.
Anthropic says the project is built with network access in an isolated virtual machine, then moved to a network without internet access for scanning. Dependencies therefore need to be fetched during image construction. The repository includes validation and local build-check tools, but its README cautions that the check command executes a project Dockerfile with network access and can reach local services unless the QEMU isolation path is used.
A useful threat model is part of the product input
The optional threat_model.md is operationally important. Anthropic recommends documenting severity rules, intended behavior, untrusted-input boundaries, important and excluded components, and preferences for reports and patches. That context can reduce findings that are technically real but irrelevant to the project’s actual security model.
Do not use the threat-model file to waive fundamental verification. Every report should still receive deduplication, reachability analysis, reproducer containment, severity reassessment, maintainer review, regression tests and coordinated release handling. Candidate patches are model output: review their full diff, test side effects and check whether they fix the root cause rather than merely suppressing the reproducer.
What maintainers should do next
Apply if the project meets the eligibility bar and already has enough security capacity to process high and critical reports. Before the pull request, create a public security alias, decide whether report encryption is required, make the build deterministic, verify tests inside the container, write the threat model and assign an owner for intake, duplicate detection, embargo handling and patch review.
Start constrained. Measure delivered reports, unique valid findings, duplicates, invalid findings, severity corrections, reproduction time, remediation time and review burden. Continue only if the added signal exceeds the triage cost without displacing existing disclosure work. Pause through the configuration flag when the queue exceeds capacity; reject enrollment when the team cannot safely receive and investigate unreviewed vulnerability reports.
Copy-ready OSS Scanner enrollment review
Complete this record before exposing a maintainer inbox and build configuration to the program.
Entries stay in this browser tab and are not submitted to AccessAllGPT. Blank responses are copied as [Unresolved].
Project impact, remote attack surface, dependent users, core maintainer, approving owner and evidence that the applicant can enroll the project.
Public security alias, backup contacts, response coverage, OpenPGP requirement, key owner, rotation plan and rules for confidential report handling.
Pinned repository and branch, Dockerfile location, deterministic dependency inputs, online build boundary, offline test result, secrets check and build owner.
Assets, trust boundaries, untrusted inputs, reachable components, out-of-scope areas, severity rubric, accepted evidence and patch expectations.
Inbox routing, duplicate search, isolated reproduction, severity reassessment, issue tracking, escalation, patch review, regression tests and maintainer response target.
Private-storage location, upstream and downstream coordination, advisory and CVE decision owner, release process, user notice and exceptions to the no-publication default.
Reports received, unique valid findings, duplicates, invalid findings, severity changes, time to reproduce, time to fix, reviewer hours and displaced security work.
Review date, capacity ceiling, pause trigger, disabled-field owner, withdrawal trigger and record of the final decision.
Primary sources
Browse the publication-wide evidence index →
- Launching an opt-in vulnerability-finding service for open-source softwareAnthropic · Reviewed: October 8, 2026 launch date; service scope; model and human-review boundary; pilot reports; 97-finding validation sample; maintainer feedback; eligibility; enrollment route; relationship to coordinated disclosure, Claude Security, Project Glasswing and Claude for OSS · Retrieved · Supports: Anthropic announced OSS Scanner on October 8 as a free, opt-in service for eligible open-source projects. Reports are generated by its strongest models, including Claude Mythos, and reach enrolled maintainers without human review or triage.
- OSS Scanner overview and FAQAnthropic Frontier Red Team · Reviewed: Overview; eligibility; maintainer verification; sign-up; project configuration; offline audit environment; report contents; disclosure policy; pause and opt-out; feedback; attribution; data security; Claude Security distinction; other maintainer support · Retrieved · Supports: The operational FAQ defines case-by-case eligibility, core-maintainer verification, public enrollment fields, Dockerfile and threat-model inputs, an offline scanning stage, private email delivery, pause and withdrawal controls, and the distinction from the enterprise Claude Security product.
- anthropics/oss-scanner enrollment repositoryAnthropic on GitHub · Reviewed: Public repository state at commit 481b73c; README enrollment steps; project.yaml fields; Dockerfile placement; threat-model guidance; local validation and build checks; post-merge process; security considerations; maintenance policy · Retrieved · Supports: The live repository provides the application path and machine-readable project template. It says the scanner builds in an isolated VM, scans without internet access, emails model-generated findings with reproducers and proposed patches where available, and does not place a 90-day public-disclosure clock on these unreviewed reports.
- Anthropic's coordinated vulnerability disclosure dashboardAnthropic Frontier Red Team · Reviewed: October 2, 2026 update timestamp; candidate, external-review, confirmed, reported, acknowledged, patched and advisory counts; assessment-source labels; severity filters; triage description; scope and glossary notices · Retrieved · Supports: The dashboard separately records Anthropic’s human-reviewed coordinated-disclosure pipeline: 29,439 candidates, 6,123 reviewed by external firms, 5,674 confirmed valid, 6,157 total reported to maintainers, 516 patched upstream and 584 CVE or GHSA identifiers as of October 2. These are vendor-maintained program counts, not OSS Scanner outcomes.
Limitations
AccessAllGPT reviewed public first-party pages and the enrollment repository but did not apply, prove project eligibility, receive acceptance, enroll a repository, build the supplied scanner environment, receive or decrypt a finding, execute Claude Mythos, inspect prompts or model snapshots, validate isolation, reproduce vulnerabilities, review patches, interview quoted maintainers, inspect non-public reports, verify dashboard records against project repositories, or measure precision, recall, severity accuracy, cadence, latency, remediation, capacity or cost. Anthropic’s 97-finding validation, wolfSSL quotation and dashboard statistics are provider-reported and may not represent future projects or scans. Access, criteria, terms, models and process can change.
Disclosures
AccessAllGPT received no Anthropic credentials, Project Glasswing access, OSS Scanner enrollment, reports, credits, briefing, private data, review, payment or compensation for this article. Anthropic and the projects quoted in its launch post did not sponsor, review or endorse it. AccessAllGPT did not test, score or rank OSS Scanner or Claude Mythos. AccessAllGPT Research is operated by NeuralArc, is independent, and is not affiliated with Anthropic, GitHub or organizations cited. Publication-wide relationships are listed on the disclosures page.
Further AccessAllGPT guidance
Continue the research
Get evidence-led updates for teams making production AI decisions.